03-15-2019 09:07 AM - edited 02-20-2020 09:45 PM
Switch(config-if)# cts manual
Switch(config-if-cts-manual)# sap pmk XXXXYYYYZZZZZ mode-list gcm-encrypt null no-encap
Switch(config-if-cts-manual)# no propagate sgt
Switch(config-if-cts-manual)# exit
NOTE: this is my config from 3560-X box with 10G service module, not the 3650-24TD-S unit, as it will not allow the gcm-encrypt option.
Any assistance is greatly appreciated!
Thanks,
Tim
03-15-2019 01:21 PM
03-19-2019 10:22 AM - edited 03-19-2019 10:24 AM
Thanks for the response. I don't see any related information in the link you provided.
Everything I read in the following documents make it sound like MACSEC encryption is supported with IPBASE AND IPSERVICES license on the 3560 platform.
Everest 16.6.x Configuration Guide for 3650
From the MACSEC Encryption Section:
The switch also supports MACsec encryption for switch-to-switch (inter-network device) security using both Cisco TrustSec Network Device Admission Control (NDAC), Security Association Protocol (SAP) and MKA-based key exchange protocol. Link layer security can include both packet authentication between switches and MACsec encryption between switches (encryption is optional).
802.1AE Tagging (MACsec) - Protocol for IEEE 802.1AE-based wire-rate hop-to-hop Layer 2 encryption.
Between MACsec-capable devices, packets are encrypted on egress from the transmitting device, decrypted on ingress to the receiving device, and in the clear within the devices.
This feature is only available between TrustSec hardware-capable devices.
From the TrustSec section:
802.1AE Tagging (MACsec)
Between MACsec-capable devices, packets are encrypted on egress from the transmitting device, decrypted on ingress to the receiving device, and in the clear within the devices.
This feature is only available between TrustSec hardware-capable devices.
This feature is not supported on Catalyst 3850 and Catalyst 3650 switches with Cisco IOS XE Denali 16.1.1
This feature is not supported on Catalyst 2960x.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide